Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting and modifying operating-system API calls that supply system information. Rootkits or rootkit-enabling functionality may reside at the user or kernel level in the operating system, or lower. (Citation: Enterprise ATT&CK January 2018) Firmware rootkits that affect the operating system yield nearly full control of the system. While firmware rootkits are normally developed for the main processing board, they can also be developed for the I/O that is attached to an asset. Compromise of this firmware allows the modification of all of the process variables and functions the module engages in. This may result in commands being disregarded and false information being fed to the main device. By tampering with device processes, an adversary may inhibit its expected response functions and possibly enable [Impact](https://attack.mitre.org/tactics/TA0105).

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Intelligent Electronic Device (IED)
is related to Virtual Private Network (VPN) Server
is related to Application Server
is related to Safety Controller
is related to Data Gateway
is related to Jump Host
is related to Programmable Logic Controller (PLC)
is related to Control Server
is related to Programmable Automation Controller (PAC)
is related to Human-Machine Interface (HMI)
is related to Firewall
is related to Field I/O
is related to Workstation
is related to Data Historian
is related to Distributed Control System (DCS) Controller
is related to Switch
is part of Inhibit Response Function
is blocked by Detection of Rootkit
is blocked by Code Signing
is blocked by Audit
Impressum Deutsch Englisch